pypykatz is a publicly available Python-based implementation of Mimikatz used for credential dumping and harvesting from Windows systems. It is a dual-use security tool rather than a distinct malware family. Threat actors deploy it after compromise to obtain account credentials, including privileged domain administrator credentials, which can support subsequent access to enterprise resources and lateral movement. It has also been packaged as a compiled executable for use in malicious operations.
Observed users include STIBNITE, APT15, Storm-0506, and Storm-2570. STIBNITE used pypykatz for credential harvesting in operations involving PoetRAT against government and wind-generation entities in Azerbaijan. APT15 used it among credential-dumping tools in a campaign targeting foreign affairs ministries in Central and South America. Storm-0506 used pypykatz alongside Cobalt Strike to steal domain administrator credentials during an intrusion against a North American engineering firm that culminated in Black Basta ransomware deployment. Storm-2570 uses it alongside Mimikatz and LaZagne in ransomware-related intrusions. These associations establish its role as post-compromise credential-access tooling, not as the mechanism responsible for initial infection, ransomware encryption, or hypervisor exploitation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Attackers combine this with credential theft (Mimikatz/Pypykatz), lateral movement (Cobalt Strike, SystemBC), and backup destruction to maximize impact and enable double-extortion.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Storm-2570 uses network scanners, then tools such as Mimikatz, LaZagne and pypykatz to obtain credentials.
The threat actor then used Cobalt Strike and Pypykatz (a Python version of Mimikatz) to steal the credentials of two domain administrators.
STIBNITE uses an executable package of a Python-based implementation of Mimikatz (PypyKatz) and the open-source LaZagne credential collection project for credential harvesting.
Mimikatz, Pypykatz, Safetykatz – Publicly available credential-dumping tools...
4 distinct techniques documented for this family, organized by ATT&CK tactic.
For credential access and harvesting, Storm-2570 uses tools like Mimikatz, LaZagne, and pypykatz.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-extraction tooling used by Storm-2570 after initial access, alongside other tools for obtaining credentials.
Credential-access and credential-harvesting tool used by Storm-2570.
Credential dumping tool present in an archive (Evidencia.rar) associated with the investigated activity; likely used for credential extraction during post-exploitation.
Python implementation of Mimikatz-like credential extraction used by attackers to dump credentials and authentication material for escalation and movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.